Effective August 17, 2026 · Last updated August 17, 2026

Privacy.

What Plinthpost stores, who can read it, and when it leaves — in plain language.

This page describes what the build actually does — not an aspirational marketing claim. If you find a discrepancy between this page and the real behavior of /api/filings, /api/drafts, or the trial-lifecycle cron, please email the address below so we can fix both at once.

1. What we store

When you start a trial, you give us three things: a trade name (Funeral Home, Pest Control, Vet Clinic, Contractor), a name and email address for the account, and optional CSV or TSV files that hold the prior-year records you want a draft against (up to 25 MB each).

When you sign in to start a packet, store runs write one account row, one intake submission row per attempt, and one file row per uploaded file. File blobs go to a per-account storage path on our filesystem (intake-storage/<accountId>/<submissionId>/…), with only the file’s metadata stored in the database.

Generated drafts — your account’s filings, the day-30 trial cut-off notices, the day-30 expired trial reminder, and the conversion receipts to Stripe — are stored in the same database under the same per-account scoping.

2. Who can see your data

Only you and a small set of Plinthpost operators can read your rows.

The data plane is auth-gated end-to-end: your account dashboard, your filings, and your draft delivery all check your signed-in session and refuse to return rows for any account other than the one you signed in to. There is no shared-link or shared-password way in — each row is hidden behind a session.

Operators (Plinthpost staff) see only what the in-product "Operator inbox" surfaces — submission rows from /intake, the same as the dashboard would — and only after they sign in with their staff account.

3. Email verification

Accounts are gated by email verification. You cannot sign in or use the product until you click the verification link we send to the email you signed up with. If our cron tries to send you a trial-ended reminder before you have verified, the reminder is skipped — your row stays in the table for the next signup pass to claim once you verify.

If you change your email, you must verify the new address before you can sign in with it.

4. Retention

We retain your filings and draft deliveries for as long as your subscription is active, plus a 90-day grace period after cancellation so you can export any data you want to keep.

After the 90-day grace period, your account rows are deleted and your uploaded files are removed from disk. Stripe keeps its own billing record per the Stripe retention rules — that is outside our control and documented at stripe.com.

If you ask us to delete your data sooner (a one-button "delete my account" inside /profile once that ships, or an email to the address below), we delete on the same next-business-day schedule.

5. What we do not do with your data

We never train a general-purpose model on your rows. We never sell your data. We never rent it. We never share it with anyone except (a) you, (b) Stripe for the billing path that you authorise, and (c) law enforcement on a properly-scoped legal demand (Plinthpost will challenge demands that are over-scoped).

We do not use third-party trackers on /intake, /dashboard, /billing, or /admin/* pages — the only tracking on the app is the Polsia analytics module shipped with the template, which records page hits without session identifiers.

6. Cookies & sessions

We use one session cookie (better-auth) so you stay signed in across pages. It expires when you sign out, when you close your browser (the default for the cookie), or after a 30-day inactivity window.

We do not place advertising cookies or cross-site identifiers anywhere in the app.

7. Changes to this page

If we make a material change to storage behavior (e.g. a new third-party processor, a longer retention period, a broader access surface), we will email the address on file at least 30 days before the change takes effect, and the “Effective” date below will move forward.

Continued use of the service after the effective date of an update constitutes acceptance of the updated policy.

8. Contact

Questions about privacy, requests to access / correct / delete data, or any other concern should be sent to the address below. Operational support requests (bugs, billing, account access) should go through the in-product support flow so they reach the right team. Email plinthpost-poypl5@polsia.app or write to Plinthpost, Inc., 8 The Green, Suite #5198, Dover, DE 19901, United States.

Document metadata

Effective date: August 17, 2026

Last updated: August 17, 2026

Document version: 1.0.0 — kept under/privacy as part of the Plinthpost public site. Mirrors Terms §3 (subscriptions) and §6 (customer data).